Vulnerability Development mailing list archives
Re: Naptha - New DoS
From: Jose Nazario <jose () BIOCSERVER BIOC CWRU EDU>
Date: Fri, 8 Dec 2000 11:45:25 -0500
On Fri, 8 Dec 2000, Lincoln Yeoh wrote:
I find it interesting that Redhat 7.0 is said to be not affected whereas Redhat 6.1 is. Why is that the case? Is it a configuration issue on 6.1?
the use of xinetd in RH7 (RH6.2 and previous used inetd) is the trick there. bear in mind that if you have either ssh (i think openssh has a MaxClients type parameter i discussed on BUGTRAQ last year, a friend submitted the patch) or Apache listening outside of xinetd, you can be attacked. Solar Designer (http://www.openwall.com/) has a patch against older versions of xinetd that limit per IP connections. simple spoofing will get around it, though. i wrote some documentation on xinetd: http://cwrulug.cwru.edu/archive/cwrulug/200011/0043.html i've been using it for some years now and its stopped process table attacks very well. naptha should also be stoppable by xinetd, with the exception of apache (you *don't* want apache in xinetd, it takes too long to handle requests). ____________________________ jose nazario jose () cwru edu PGP: 89 B0 81 DA 5B FD 7E 00 99 C3 B2 CD 48 A0 07 80 PGP key ID 0xFD37F4E5 (pgp.mit.edu)
Current thread:
- Re: Naptha - New DoS, (continued)
- Re: Naptha - New DoS Carl-Johan Bostorp (Dec 08)
- Re: Naptha - New DoS White Vampire (Dec 09)
- Message not available
- Re: Naptha - New DoS White Vampire (Dec 09)
- Re: Naptha - New DoS rpc (Dec 09)
- Re: Naptha - New DoS Sebastian (Dec 10)
- Re: Naptha - New DoS Damian Menscher (Dec 10)
- Re: Naptha - New DoS Filipe Almeida (Dec 16)
- Re: Naptha - New DoS Bruno Morisson (Dec 17)
- Re: Naptha - New DoS White Vampire (Dec 09)
- Re: Naptha - New DoS Carl-Johan Bostorp (Dec 08)
- Re: Naptha - New DoS Lincoln Yeoh (Dec 09)
- Re: Naptha - New DoS Michael H. Warfield (Dec 09)
- Re: Naptha - New DoS Jose Nazario (Dec 09)
- Re: Naptha - New DoS Ron DuFresne (Dec 09)
- Message not available
- Re: Naptha - New DoS Lincoln Yeoh (Dec 09)
- Re: Naptha - New DoS Simple Nomad (Dec 11)
- Re: Naptha - New DoS Dug Song (Dec 11)
- Re: Naptha - New DoS Stephane Aubert (Dec 12)
- Re: Naptha - New DoS AV (Dec 12)
- Re: Naptha - New DoS Damian Menscher (Dec 13)
- Re: Naptha - New DoS Ryan Permeh (Dec 15)